<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paranoid Prose &#187; online security</title>
	<atom:link href="http://www.paranoidprose.com/category/online-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paranoidprose.com</link>
	<description>reading to keep you up at night</description>
	<lastBuildDate>Thu, 29 Jul 2010 13:10:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>hiding in plain sight&#8230; or not</title>
		<link>http://www.paranoidprose.com/2010/07/14/hiding-in-plain-sight-or-not/</link>
		<comments>http://www.paranoidprose.com/2010/07/14/hiding-in-plain-sight-or-not/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 22:46:15 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[hacks]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=407</guid>
		<description><![CDATA[One of the revelations from the recent capture of a number of deep cover Russian spies here in the US was that they used steganography (the concealment of data within innocuous looking files) in order to hide and transmit secret documents and messages to their handlers.  Steganography is one of those techniques which get talked [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_410" class="wp-caption alignleft" style="width: 310px"><img class="size-medium wp-image-410" title="SecretBunker" src="http://www.paranoidprose.com/wp-content/uploads/2010/07/SecretBunker-300x225.jpg" alt="Sometimes, the best place to hide things is in plain sight..." width="300" height="225" /><p class="wp-caption-text">Sometimes, the best place to hide things is in plain sight...</p></div>
<p>One of the revelations from the recent capture of a number of deep cover Russian spies here in the US was that t<a href="http://www.msnbc.msn.com/id/38028696/ns/technology_and_science-science/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.msnbc.msn.com/id/38028696/ns/technology_and_science-science/?referer=');">hey used steganography </a>(the concealment of data within innocuous looking files) in order to hide and transmit secret documents and messages to their handlers.  <a href="http://en.wikipedia.org/wiki/Steganography#External_links" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Steganography_External_links?referer=');">Steganography</a> is one of those techniques which get talked about a lot a security conferences, but has not seemed to play a major role in news of security breaches.  This seems a bit odd to me &#8211; stego seems like a great way to exfiltrate information in plain sight.  By embedding ill gotten data in vacation pictures posted to Flickr or Facebook, spies (corporate or otherwise) can create very low risk electronic <a href="http://en.wikipedia.org/wiki/Dead_drop" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Dead_drop?referer=');">dead drops</a> with a few mouse clicks.  Unlike encryption, stego does not leave suspicious encrypted files to exfiltrate, just innocent looking pictures or songs.  The software needed to create stego protected files is available <a href="ftp://ftp.funet.fi/pub/crypt/mirrors/idea.sec.dsi.unimi.it/code/s-tools4.zip" target="_blank">on the Net</a>.  So why (other than some articles about <a href="http://www.usatoday.com/tech/columnist/2001/12/19/maney.htm" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.usatoday.com/tech/columnist/2001/12/19/maney.htm?referer=');">Al Qaeda reportedly using stego to embed secret information in internet images</a>) do we not hear more about this technique?  I have a couple of hypotheses here:</p>
<p><strong>Attackers are using stego, but they are not getting caught.</strong> Detection of files with steganographically hidden content is very difficult, requiring very specialized knowledge and tools which most enterprises and forensic examiners don&#8217;t have access to.</p>
<p><strong>Attackers don&#8217;t need to use stego because they don&#8217;t need to. </strong>There are so many organizations out there who do not have a handle on what information is leaving their networks, that they don&#8217;t feel the need to go to the trouble of hiding the information they are swiping.  Or they are using really low tech methods to get the data out of the organization, like printing, or fax, or <a href="http://www.u3.se/images/Postpictures/U%208_052.jpg" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.u3.se/images/Postpictures/U_208_052.jpg?referer=');">this</a>.</p>
<p>Is stego a real threat to the enterprise?  I am not sure.  But the availability of stego underlines the need to build a security culture in your organization and use both technology and non tech means to detect potential problems.  Stego seems to be a tool which insiders would be predisposed to use &#8211; detecting insider threats takes both technology and plain old vigilance.  There is some <a href="http://www.cert.org/insider_threat/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.cert.org/insider_threat/?referer=');">excellent information on detecting insider threats </a>available from the CERT team &#8211; this should be on your reading list.</p>
<p><em>This post was inspired by Kai Axford&#8217;s (Accretive Solutions) great presentation at today&#8217;s <a href="https://www.nym-infragard.us/cms/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.nym-infragard.us/cms/?referer=');">New York Metro InfraGard</a> meeting.</em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F14%2Fhiding-in-plain-sight-or-not%2F&amp;linkname=hiding%20in%20plain%20sight%26%238230%3B%20or%20not" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F14_2Fhiding-in-plain-sight-or-not_2F_amp_linkname=hiding_20in_20plain_20sight_26_238230_3B_20or_20not&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/14/hiding-in-plain-sight-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>giving away the plans to the fort?</title>
		<link>http://www.paranoidprose.com/2010/07/11/is-microsoft-betraying-the-united-states/</link>
		<comments>http://www.paranoidprose.com/2010/07/11/is-microsoft-betraying-the-united-states/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 21:10:20 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[deep thoughts]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=368</guid>
		<description><![CDATA[OK, call me a cold war relic, but I find the recent revelation that Microsoft has provided the source code for Windows, SQL Server, and Office to the Russian FSB (the spies formerly known as the KGB) as well as to the Chinese government quite disturbing. As recent events prove, Russia is still actively engaged [...]]]></description>
			<content:encoded><![CDATA[<p><strong> </strong></p>
<div class="wp-caption alignleft" style="width: 273px"><img class=" " title="traitor" src="http://larussophobe.files.wordpress.com/2009/10/traitor1.jpg" alt="" width="263" height="366" /><p class="wp-caption-text">Is Microsoft a cyber-Benedict Arnold?</p></div>
<p><strong>OK, call me a cold war relic, but I find the recent revelation that </strong><a href="http://www.zdnet.co.uk/news/security/2010/07/08/microsoft-opens-source-code-to-russian-secret-service-40089481/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.zdnet.co.uk/news/security/2010/07/08/microsoft-opens-source-code-to-russian-secret-service-40089481/?referer=');"><strong>Microsoft has provided the source code for Windows, SQL Server, and Office to the Russian FSB (the spies formerly known as the KGB)</strong></a><strong> </strong><strong>as well as to the <a href="http://www.informationweek.com/news/software/operatingsystems/showArticle.jhtml?articleID=225400063" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.informationweek.com/news/software/operatingsystems/showArticle.jhtml?articleID=225400063&amp;referer=');">Chinese government </a>quite disturbing. </strong>As <a href="http://topics.nytimes.com/top/reference/timestopics/subjects/r/russian_spy_ring_2010/index.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/topics.nytimes.com/top/reference/timestopics/subjects/r/russian_spy_ring_2010/index.html?referer=');">recent events</a> prove, Russia is still actively engaged in espionage against the US public and private sectors.  We know that the Chinese People&#8217;s Liberation Army is <a href="http://online.wsj.com/article/SB10001424052748703399204574508413849779406.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/online.wsj.com/article/SB10001424052748703399204574508413849779406.html?referer=');">actively building an offensive cyber capability</a> and that they use technology to suppress free expression in their country.  Microsoft&#8217;s disclosures have been going on since 2002, as part of a program under which Microsoft has supplied source code for its products to a number of countries as well as NATO.</p>
<p>It does not take too much imagination to conjure up visions of Russian or Chinese  government security researchers finding zero-day exploits to allow their paymasters to craft undetectable malware which is then placed on US government and private sector computers.  Such an attack would be a cost effective, low risk way to gather more information in a day than the recently unmasked spy ring was able to collect over a decade.   It takes even less imagination to envision the Chinese government using their access to Windows source code to build more efficient tools to monitor and muzzle those who dare to speak out against the Communist Party.</p>
<p>This incident raises a number of  interesting questions.</p>
<p>Is Microsoft (a company born in America, whose success was built on the US market, and which benefits from <a href="http://crosscut.com/2008/02/02/microsoft/11167/Microsoft-s-$528-million-Washington-tax-break/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/crosscut.com/2008/02/02/microsoft/11167/Microsoft-s-_528-million-Washington-tax-break/?referer=');">tax breaks funded by US taxpayers</a>) right to provide access to source code of products which are the underpinnings of all sorts of critical infrastructure to nations which are actively engaged in espionage against the US and whom we may meet on the cyber battlefield of the future?  It seems to me that this is sort of like hiring a company to build a fort and then allowing them sell the plans to your adversaries.</p>
<p>Should Microsoft&#8217;s products have some sort of special status which recognizes them as part of the US critical infrastructure?  After all, Microsoft has been allowed to gain what is basically a monopoly in the US market for operating systems and other key software.  Does this engender a responsibility on their part to act in accordance with US national interests?   I think it does.</p>
<p>Microsoft hasn&#8217;t done anything illegal here.  It would be nice if they felt a need to protect the critical infrastructure of their country, but as a private entity with no laws or regulations to prevent their actions, they made the logical <em>business</em> decision to share the source code in order to gain better access to the Russian and Chinese markets.   However, their choice is a bum deal for the rest of us, who will have to deal with the repercussions of this decision while Microsoft reaps the profits.  We need to tell our legislators that it is time to take a fresh look at what we ask of companies like Microsoft and Cisco, whom we have allowed to develop monopolies on key parts of the nation&#8217;s critical infrastructure.  In the conflicts yet to come, cyberspace will play a key role &#8211; and Microsoft has sold the plans for the fort to potential adversaries.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F11%2Fis-microsoft-betraying-the-united-states%2F&amp;linkname=giving%20away%20the%20plans%20to%20the%20fort%3F" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F11_2Fis-microsoft-betraying-the-united-states_2F_amp_linkname=giving_20away_20the_20plans_20to_20the_20fort_3F&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/11/is-microsoft-betraying-the-united-states/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>skype crypto reverse engineered &#8211; world continues rotating</title>
		<link>http://www.paranoidprose.com/2010/07/10/skype-crypto-reverse-engineered-world-continues-rotating/</link>
		<comments>http://www.paranoidprose.com/2010/07/10/skype-crypto-reverse-engineered-world-continues-rotating/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 00:48:36 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[hacks]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=361</guid>
		<description><![CDATA[Here&#8217;s an interesting story that bears some watching&#8230; security researcher Sean O&#8217;Neill claims to have reverse engineered the proprietary encryption which Skype uses to protect voice, video and IM communications on its network.    This work, while impressive, does not mean that Skype&#8217;s encryption has been broken, since knowing the details of an encryption algorithm does not [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 310px"><img title="Eavesdrop" src="http://jamesrenner.files.wordpress.com/2009/12/wiretap.jpg" alt="" width="300" height="300" /><p class="wp-caption-text">something new for the po-po to listen to?</p></div>
<p>Here&#8217;s an interesting story that bears some watching&#8230; security researcher Sean O&#8217;Neill <a href="http://news.softpedia.com/news/Skype-s-Encryption-Scheme-Possibly-Broken-146842.shtml" target="_blank" onclick="pageTracker._trackPageview('/outgoing/news.softpedia.com/news/Skype-s-Encryption-Scheme-Possibly-Broken-146842.shtml?referer=');">claims to have reverse engineered the proprietary encryption which Skype uses to protect voice, video and IM communications</a> on its network.    This work, while impressive, does not mean that Skype&#8217;s encryption has been broken, since knowing the details of an encryption algorithm does not allow you to decrypt data unless you can also derive the keys used to encrypt the data.  However, there are some reports that the O&#8217;Neill&#8217;s code has been used to launch spam attacks on Skype users.  I am sure that intelligence and law enforcement agencies all over the world are quite interested in how this all turns out, as they have complained in the past that Skype provides criminals, terrorists and other n&#8217;er do wells with <a href="http://www.atelier-us.com/internet-usage/article/criminals-use-voip-to-avoid-wiretaps" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.atelier-us.com/internet-usage/article/criminals-use-voip-to-avoid-wiretaps?referer=');">un-wiretap-able communications</a>.  O&#8217;Neill plans to provide more information on his work at the Chaos Computer Congress in December. </p>
<p>In the mean time, I plan to continue using Skype without too much worry.  Of course, I&#8217;ll think twice about using it for coordinating the global tentacles of my evil plan for world domination, but I see no reason to avoid Skype for personal and business communications right now.  Stay tuned.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F10%2Fskype-crypto-reverse-engineered-world-continues-rotating%2F&amp;linkname=skype%20crypto%20reverse%20engineered%20%26%238211%3B%20world%20continues%20rotating" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F10_2Fskype-crypto-reverse-engineered-world-continues-rotating_2F_amp_linkname=skype_20crypto_20reverse_20engineered_20_26_238211_3B_20world_20continues_20rotating&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/10/skype-crypto-reverse-engineered-world-continues-rotating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>robin sage ain&#8217;t your friend&#8230;</title>
		<link>http://www.paranoidprose.com/2010/07/08/robin-sage-aint-your-friend/</link>
		<comments>http://www.paranoidprose.com/2010/07/08/robin-sage-aint-your-friend/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 00:57:06 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=346</guid>
		<description><![CDATA[You can never have too many friends &#8211; or CAN you?  (Hint: you can).   A recent social engineering experiment conducted by Thomas Martin of Provide Security showed the dangers of blindly accepting connection requests from people on social networks.  Martin set up multiple social network profiles for a fictitious person named Robin Sage who [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 83px"><img title="Robin Sage" src="http://a1.twimg.com/profile_images/593868778/Robin1_bigger.png" alt="" width="73" height="73" /><p class="wp-caption-text">Wanna be friends?</p></div>
<p>You can never have too many friends &#8211; or CAN you?  (Hint: you can).   A recent social engineering experiment conducted by Thomas Martin of Provide Security showed the dangers of blindly accepting connection requests from people on social networks.  Martin set up multiple social network profiles for a fictitious person named Robin Sage who supposedly worked in US military intelligence circles.  &#8220;Robin&#8221; then sent connection requests to a variety of people in the security and intel communities (people who should know better, in other words).  The result?  In <a href="http://www.csoonline.com/article/598906/the-robin-sage-experiment-fake-profile-fools-security-pros?page=1" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.csoonline.com/article/598906/the-robin-sage-experiment-fake-profile-fools-security-pros?page=1&amp;referer=');">an interview with CSO Magazine</a>, he stated that:</p>
<p style="padding-left: 30px;"><em>By the end of the 28-day experiment, Robin finished the month having  accumulated hundreds of connections through various social networking  sites. Contacts included executives at government entities such as the  NSA, DOD and Military Intelligence groups. Other friends came from  Global 500 corporations. Throughout the experiment Robin was offered  gifts, government and corporate jobs, and options to speak at a variety  of security conferences, said Ryan.</em></p>
<address style="padding-left: 30px;"> </address>
<address style="padding-left: 30px;"> </address>
<p>More alarmingly, according to an <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=225702468" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=225702468&amp;referer=');">article from DarkReading</a>,</p>
<p style="padding-left: 30px;"><em>Robin actually duped an Army Ranger into  friending her. The Ranger then inadvertently exposed information about  his coordinates in Afghanistan to Robin with his uploaded photos from  the field that contained GeoIP data from the camera.</em></p>
<p>Can you spell &#8220;bad operational security?&#8221;</p>
<p>Martin will be revealing all of his findings from the Robin Sage experiment in a talk at Black Hat later this month &#8211; should be quite entertaining for most and deeply embarrassing for a few.</p>
<p>There are some lessons learned to be learned from this incident for those of us who are not part of the military:</p>
<p style="padding-left: 30px;"><strong>If you get a friend/connection request from someone you don&#8217;t know, don&#8217;t blindly accept it. </strong>When you bring someone into your online network, you are also granting them access to information about you (contact information, status updates, photos, etc.) as well as your organization (in the case of professional networking sites like LinkedIn)</p>
<p style="padding-left: 30px;"><strong>Just because a &#8220;new friend&#8221; is already connected to some of your current friends does not mean that you should connect to them.</strong> All it takes is one careless connection to start an &#8220;avalanche of (misplaced) trust&#8221; and give an evildoer lots of information about yourself and your organization.  Trust me &#8211; I have seen this happen.  You know who you are.</p>
<p style="padding-left: 30px;"><strong>Review the privacy settings for your social networking accounts and be sure that you are aware of and comfortable with the information that is shared with the public at large and with your &#8220;friends.&#8221; </strong> The privacy settings in Facebook and Linked In are rather complex.  I recommend using a privacy scanner tool to keep an eye on who can see what on your profiles&#8230; I really like one called <a href="http://apps.facebook.com/privacydefender" target="_blank" onclick="pageTracker._trackPageview('/outgoing/apps.facebook.com/privacydefender?referer=');">Privacy Defender for Facebook</a>, which allows you to easily see and modify who can and cannot see your info.  For LinkedIn, it seems like the only way to manage your privacy is manually via the Settings menu; it is sort of a pain, but the explanations provided by the site are pretty good.</p>
<p>And Robin Sage ain&#8217;t your friend.</p>
<p>PS &#8211; &#8220;Robin Sage&#8221; is the code name for the <a href="http://www.globalsecurity.org/military/ops/robin-sage.htm" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.globalsecurity.org/military/ops/robin-sage.htm?referer=');">last training exercise that Army Rangers must complete before they are truly &#8220;Green Berets&#8221;</a> &#8211; and none of the military folks (including at least one Ranger) caught on.  Sigh&#8230;</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F08%2Frobin-sage-aint-your-friend%2F&amp;linkname=robin%20sage%20ain%26%238217%3Bt%20your%20friend%26%238230%3B" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F08_2Frobin-sage-aint-your-friend_2F_amp_linkname=robin_20sage_20ain_26_238217_3Bt_20your_20friend_26_238230_3B&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/08/robin-sage-aint-your-friend/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>porn and malware redux</title>
		<link>http://www.paranoidprose.com/2010/07/05/porn-and-malware-redux/</link>
		<comments>http://www.paranoidprose.com/2010/07/05/porn-and-malware-redux/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 23:04:45 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=343</guid>
		<description><![CDATA[A few weeks back, I blogged about some research on the economics and potential malware risks posed by Internet pornography.  Well, a *new* study from Avast Software finds that non pornographic sites serving up malware outnumber pornographic sites serving malware by a factor of almost 100 to one.  Furthermore, Avast contends that there are more malware infected [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_344" class="wp-caption alignleft" style="width: 309px"><a href="http://www.paranoidprose.com/wp-content/uploads/2010/07/NewYorkSocietyForTheSuppressionOfVice.jpg"><img class="size-medium wp-image-344" title="NewYorkSocietyForTheSuppressionOfVice" src="http://www.paranoidprose.com/wp-content/uploads/2010/07/NewYorkSocietyForTheSuppressionOfVice-299x300.jpg" alt="" width="299" height="300" /></a><p class="wp-caption-text">Did they have it all wrong?</p></div>
<p>A few weeks back, I <a href="http://www.paranoidprose.com/2010/06/13/porn-economics-and-security-but-mostly-porn/" target="_blank">blogged</a> about some research on the economics and potential malware risks posed by Internet pornography.  Well, <a href="http://www.avast.com/pr-legitimate-websites-outscore-the-adult" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.avast.com/pr-legitimate-websites-outscore-the-adult?referer=');">a *new* study from Avast Software</a> finds that non pornographic sites serving up malware outnumber pornographic sites serving malware by a factor of almost 100 to one.  Furthermore, Avast contends that there are more malware infected domains containing the word &#8220;London&#8221; than there are containing the word &#8220;sex.&#8221;  Not sure what this says about London.  I guess the morals of the story are:  for every study claiming fact x, there will be one claiming fact y and that the internet is as dangerous a place for the vituous as it is for the naughty.  Have<strong> you</strong> updated your antivirus and <a href="http://www.mozilla.com/en-US/plugincheck/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.mozilla.com/en-US/plugincheck/?referer=');">plugins</a> lately?</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F05%2Fporn-and-malware-redux%2F&amp;linkname=porn%20and%20malware%20redux" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F05_2Fporn-and-malware-redux_2F_amp_linkname=porn_20and_20malware_20redux&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/05/porn-and-malware-redux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>slicing the salami in the 21st century</title>
		<link>http://www.paranoidprose.com/2010/06/28/slicing-the-salami-in-the-21st-century/</link>
		<comments>http://www.paranoidprose.com/2010/06/28/slicing-the-salami-in-the-21st-century/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 21:22:02 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[hacks]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=329</guid>
		<description><![CDATA[According to an interesting story at Wired&#8217;s Danger Room blog, the FTC has filed a lawsuit against a number of &#8220;John Doe&#8221; defendants who stole more than $10 million dollars from 1.3 million credit card holders since 2006.  Using a variety of shell companies and money mules recruited via online advertising for work at home [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Salami" src="http://www.hungariandeli.com/images/salami.gif" alt="Lotsa slices = a big salami" width="229" height="374" />According to an <a href="http://www.wired.com/threatlevel/2010/06/ftc-sues-scammers" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.wired.com/threatlevel/2010/06/ftc-sues-scammers?referer=');">interesting story at Wired&#8217;s Danger Room blog</a>, the FTC has filed a lawsuit against a number of &#8220;John Doe&#8221; defendants who stole more than $10 million dollars from 1.3 million credit card holders since 2006.  Using a variety of shell companies and money mules recruited via online advertising for work at home jobs, the unidentified defendants made small (20 cents to 10 dollar) charges to victims&#8217; credit cards.  Each card was charged only once, but at 1.3 million cards, we&#8217;re talking some serious coin here.  In addition to being evil, this scheme was pretty smart &#8211; since the charges were so small, most people (90% in this case) never bothered to dispute them &#8211; after all, how much time are you willing to spend disputing a charge for a couple of bucks?   While the FTC has identified some of the mules, the ringleaders remain unknown. </p>
<p>In the old days, this type of scam was called &#8220;<a href="http://en.wikipedia.org/wiki/Salami_slicing" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Salami_slicing?referer=');">salami slicing</a>&#8221; &#8211; stealing just a little bit (one slice of salami) from a lot of people adds up to a big salami.   Mmmmmm&#8230;. salami&#8230;. </p>
<p>This is a really hard type of fraud to fight&#8230; since so few of the charges were contested, it took 4 years for and credit card issuers and feds to find a pattern.  In the mean time, all of the victims suffered very small losses.  The ringleaders got their millions and are still on the lam (eating salami and caviar sandwiches, I assume).</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F06%2F28%2Fslicing-the-salami-in-the-21st-century%2F&amp;linkname=slicing%20the%20salami%20in%20the%2021st%20century" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F06_2F28_2Fslicing-the-salami-in-the-21st-century_2F_amp_linkname=slicing_20the_20salami_20in_20the_2021st_20century&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/06/28/slicing-the-salami-in-the-21st-century/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>porn, economics, and security (but mostly porn)</title>
		<link>http://www.paranoidprose.com/2010/06/13/porn-economics-and-security-but-mostly-porn/</link>
		<comments>http://www.paranoidprose.com/2010/06/13/porn-economics-and-security-but-mostly-porn/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 02:17:03 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=311</guid>
		<description><![CDATA[As we all know, the Internet is a series of tubes invented by Al Gore to allow us to exchange cute cat pictures and pornography. This past week, a paper presented at the Ninth Workshop on the Economics of Information Security provided some really interesting insight into both the economics of the Internet pornography industry [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Burlesque" src="http://joyunconfined.net/vbs/wp-content/uploads/2009/03/3466burlesque-posters.jpg" alt="" width="330" height="425" /><strong>As we all know, the Internet is a series of tubes invented by Al Gore to allow us to exchange cute cat pictures and </strong><a href="http://www.youtube.com/watch?v=NiFD6EFVsTg" onclick="pageTracker._trackPageview('/outgoing/www.youtube.com/watch?v=NiFD6EFVsTg&amp;referer=');"><strong>pornography</strong></a><strong>. </strong> This past week, a paper presented at the <a href="http://weis2010.econinfosec.org/program.html" onclick="pageTracker._trackPageview('/outgoing/weis2010.econinfosec.org/program.html?referer=');">Ninth Workshop on the Economics of Information Security</a> provided some really interesting insight into both the economics of the Internet pornography industry and more importantly, how those economics translate into security considerations.</p>
<p>The research in question was conducted by a team of researchers from the Technical University of Vienna, Institute Eurecom, and UC Santa Barbara.  <em>A brief digression here… if I had been informed that conducting studies of Internet porn was an option, I definitely would have finished college and gone into academia.  We should let kids know about this so that they stay in school!</em></p>
<p><span id="more-311"></span>Any-who… Our lucky, lucky, research team found that pornography accounts for 12% of web pages on the Internet and that the porn industry was worth over $97 billion in 2006.   For some perspective, this is more than the combined revenues of Microsoft, Google, Apple, Amazon, eBay and Yahoo! Combined.  And this is in spite of the absolute torrent of free porno to be found on the net.  (Or so I have been told.)</p>
<p>Much of the paper was devoted to describing just how the porno ecosystem can be so lucrative.  My interest, though was purely from a security perspective…</p>
<p>Researchers found that 3.23 percent of the adult web site pages they examined “were found to trigger malicious behavior such as code execution, registry changes, or executable down- loads.”  However, many of the evil pages show signs that their malware payloads were the results of hackers compromising the adult sites.  In these cases, it would seem that the attackers are taking advantage of the high traffic rates to expose their ‘sploits to the largest possible audience.</p>
<p>The researchers then went a step further, actually setting up two adult web sites and registering with affiliate programs and traffic brokers to lure unwary pornophiles to participate in their research (although no perverts were harmed in the course of the study.)  These sites were configured to collect information about their visitors’ computers, noting browser and plug in versions as well as performing specific checks for vulnerable plugins used to handle Word and PDF documents.  The researchers then bought 49,000 visitors from the traffic brokers (for about USD 160) and analyzed their visitors.  Of the 49,000 visitors, the researchers were able to build complete browser profiles for just under half.  After further analysis, just over 20,000 of the visitors were found to have one or more of the vulnerabilities that the researchers were scanning for.  Almost 6,000 users had multiple vulnerabilities.</p>
<p>Now in this case, no malware was installed on the unwitting experiment participants, but had the researchers had nefarious intent in mind, they could have put together a 20,000 node botnet for just a couple of hundred dollars.  (Actually, they could have offset their costs by installing other ad/spy/scareware on their prey.)</p>
<p>The take aways?  First, this was an excellent, enlightening and engrossing <a href="http://weis2010.econinfosec.org/papers/session2/weis2010_wondracek.pdf" onclick="pageTracker._trackPageview('/outgoing/weis2010.econinfosec.org/papers/session2/weis2010_wondracek.pdf?referer=');">paper</a> which I highly recommend reading – the economics of Internet porn really interesting.  Second, surfing porn does pose a small but non zero risk – one which was significantly higher than shown in previous research.  There is not enough data here to show a trend of increasing risk, but it would make sense, given the cost effectiveness of porn as a malware vector, that cybercriminals would increasingly look to this method of building botnets.</p>
<p>Now if you’ll excuse me, I have some research, yeah, research to attend to…</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F06%2F13%2Fporn-economics-and-security-but-mostly-porn%2F&amp;linkname=porn%2C%20economics%2C%20and%20security%20%28but%20mostly%20porn%29" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F06_2F13_2Fporn-economics-and-security-but-mostly-porn_2F_amp_linkname=porn_2C_20economics_2C_20and_20security_20_28but_20mostly_20porn_29&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/06/13/porn-economics-and-security-but-mostly-porn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>is your browser going to rat you out?</title>
		<link>http://www.paranoidprose.com/2010/05/31/is-your-browser-going-to-rat-you-out/</link>
		<comments>http://www.paranoidprose.com/2010/05/31/is-your-browser-going-to-rat-you-out/#comments</comments>
		<pubDate>Mon, 31 May 2010 10:21:28 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[online security]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=292</guid>
		<description><![CDATA[Your browser is a dirty stinkin rat.  There&#8230; I said it.  According to research conducted by the Electronic Frontier Foundation (EFF), most browsers have telltale fingerprints which can be used by web site owners to uniquely identify visitors to their sites even if cookies are disabled, or the visitor is coming from behind a NATting [...]]]></description>
			<content:encoded><![CDATA[<p><a href="null"><img class="alignleft" title="Inflatable rat" src="http://img9.imageshack.us/img9/7987/inflatablerat.jpg" alt="" width="189" height="329" /></a>Your browser is a dirty stinkin rat.  There&#8230; I said it.  According to <a href="http://panopticlick.eff.org" target="_blank" onclick="pageTracker._trackPageview('/outgoing/panopticlick.eff.org?referer=');">research conducted by the Electronic Frontier Foundation (EFF), </a>most browsers have telltale fingerprints which can be used by web site owners to uniquely identify visitors to their sites even if cookies are disabled, or the visitor is coming from behind a NATting firewall.   </p>
<p>The Panopticlick software developed by the EFF researchers looks at a wide variety of information which a web site can gather from any visiting client.  By combining a number of these seemingly innocuous pieces of information, a client fingerprint can be calculated:</p>
<p>Browser and plugin versions</p>
<p>Configuration options</p>
<p>ACCEPT headers</p>
<p>Screen resolution</p>
<p>Fonts</p>
<p>Time Zones</p>
<p>MIME types</p>
<p>The EFF collected its data via a website which it set up and publicized, so we can assume that the data they collected came from people who are interested in their privacy.  Despite this self selected sample, the findings do not bode well for privacy on the Internet:</p>
<ul>
<li>Overall, the browsers of 83.6% of all visitors to the test site had unique fingerprints.</li>
</ul>
<p> </p>
<ul>
<li>If a browser has Adobe Flash or the Java Virtual Machine enabled, there was a 94.2% chance that its fingerprint was unique.</li>
</ul>
<p> </p>
<ul>
<li>Since the fingerprints are based on browser configuration settings, they can change rapidly.  However, the researchers were able to detect changed fingerprints and tie them back to the original fingerprint in 99.1% of cases via an algorithm.</li>
</ul>
<p> </p>
<ul>
<li>Some good news for mobile device users &#8211; iPhone and Android based browsers had more uniform fingerprints and were harder to differentiate from one another due to the lack of plugins and options available.  However, as mobile browsers become more sophisticated, this technique may become applicable to these browsers on the go.  Also, it is important to note that the mobile browsers do not have good ways to control cookies, leaving them open to cookie based fingerprinting.</li>
</ul>
<p>In related work, <a href="http://www.newscientist.com/article/dn18924-history-of-social-network-use-reveals-your-identity.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.newscientist.com/article/dn18924-history-of-social-network-use-reveals-your-identity.html?referer=');">researchers from an Australian university have found that they were able to identify by name many users of Xing, a social networking site in Germany</a>.  The researchers first collected information on 6500 groups and their 1.8 million members.  By simply analyzing the overlaps in group memberships, they were able to discern the identities of 42% of the users.  They next created a web site which, when visited, examined the browser history of the visitor.  Of the 26 test subjects they enlisted, the identities of 15% were revealed simply by visiting the site.  Xing has updated their software to protect against these types of attacks, but other sites may still be vulnerable.</p>
<p>So&#8230; what does this all mean?  Well, first of all, marketers and site owners have a new tool to track visitors, including those who have disabled cookies (in order to avoid such tracking).   Second of all, these techniques provide scammers and malware authors with a way to track their victims&#8217; web activity without leaving telltale traces.  On the bright side, these fingerprinting techniques could also be used for good purposes, such as providing an additional level of authentication for banking and other sensitive web sites (and there is evidence that this is already being done, although mostly using cookies).  Law enforcement could use these techniques during investigations, although given the politics of many nations, this could be a really bad thing as well.  The EFF wants policymakers to expand their definition of personnally identifiable information to include fingerprintable records &#8211; I think that this is a topic worthy of discussion.  I also think that browser designers need to work on this problem from a technical point of view.</p>
<p>Want to cover your tracks?  Well, you could block Javascript &#8211; this provides pretty good protection against the techniques EFF used, but at a cost in terms of web site usability and functionality.  You could start using <a href="http://outgoing.mozilla.org/v1/04d7f68792fb05859c5a78c50b2bd5652ce99983/https%3A//www.torproject.org/torbutton" target="_blank" onclick="pageTracker._trackPageview('/outgoing/outgoing.mozilla.org/v1/04d7f68792fb05859c5a78c50b2bd5652ce99983/https_3A//www.torproject.org/torbutton?referer=');">TorButton</a> to route your web traffic via anonymizing proxies.  You could use your iPhone or Android phone to do all your web surfing.  None of these solutions is ideal.</p>
<p>So&#8230; another nail in the coffin of privacy&#8230;</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F05%2F31%2Fis-your-browser-going-to-rat-you-out%2F&amp;linkname=is%20your%20browser%20going%20to%20rat%20you%20out%3F" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F05_2F31_2Fis-your-browser-going-to-rat-you-out_2F_amp_linkname=is_20your_20browser_20going_20to_20rat_20you_20out_3F&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/05/31/is-your-browser-going-to-rat-you-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>terabits (and risks) under the sea</title>
		<link>http://www.paranoidprose.com/2010/05/30/terabits-and-risks-under-the-sea/</link>
		<comments>http://www.paranoidprose.com/2010/05/30/terabits-and-risks-under-the-sea/#comments</comments>
		<pubDate>Sun, 30 May 2010 20:20:08 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=282</guid>
		<description><![CDATA[Satellites get all the glamor with their showy rocket liftoffs and space shuttle missions, but in reality, over 99% of intercontinental data traffic travels via undersea cables which crisscross the planet&#8217;s briny depths.  These vital telephone and Internet links are exposed to a number of dangers ranging from seismic activity to misplaced ships&#8217; anchors and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Undersea Cables" src="http://www.cloudave.com/getImage.act?id=50000000109289" alt="" width="400" height="518" /><strong>Satellites get all the glamor with their showy rocket liftoffs and space shuttle missions, but in reality, over 99% of intercontinental data traffic travels via undersea cables which crisscross the planet&#8217;s briny depths.</strong>  These vital telephone and Internet links are exposed to a number of dangers ranging from seismic activity to misplaced <a href="http://www.guardian.co.uk/business/2008/feb/01/internationalpersonalfinancebusiness.internet" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.guardian.co.uk/business/2008/feb/01/internationalpersonalfinancebusiness.internet?referer=');">ships&#8217; anchors</a> and <a href="http://www.ukcpc.org.uk/cable-safety.asp" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.ukcpc.org.uk/cable-safety.asp?referer=');">fishing gear</a>, to pirates and <a href="http://lirneasia.net/2007/06/vietnams-submarine-cable-lost-and-found/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/lirneasia.net/2007/06/vietnams-submarine-cable-lost-and-found/?referer=');">cable thieves</a>, and when one of these links is broken, the effects can span countries or continents.  Upping the risk level is the fact than a large number of cables converge at a small number of geographic choke points such as the Suez Canal, and the Malacca and Luzon Straits.  When cables in these areas are damaged, there is a domino effect as traffic has to be rerouted to avoid the break.</p>
<p>In April of this year, the SeaMeWe-4 cable, which carries 89% of the traffic between the Middle East and Europe, <a href="http://gigaom.com/2010/04/19/cable-cut-disrupts-internet-traffic-in-middle-east-europe/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/gigaom.com/2010/04/19/cable-cut-disrupts-internet-traffic-in-middle-east-europe/?referer=');">was cut</a>, severly impacting Internet and telephone communications between the two areas.  In 2008, a<a href="http://en.wikipedia.org/wiki/2008_submarine_cable_disruption" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/2008_submarine_cable_disruption?referer=');"> series of cable cuts </a>in the Middle East disrupted network access and spawned a number of conspiracy theories due to the fact that neither Iraq or Israel were affected.  Back in 2006<a href="http://www.zdnetasia.com/earthquake-knocks-out-asian-communications-61977997.htm" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.zdnetasia.com/earthquake-knocks-out-asian-communications-61977997.htm?referer=');">, a major earthquake cut the APCN2 cable </a>connecting China, Hong Kong and other Asian countries bringing online commerce to a halt for days and resulting in network performance disruptions for months.</p>
<p>The good news is that notice is being taken &#8211; the IEEE held a &#8220;<a href="http://www.ieee-rogucci.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.ieee-rogucci.org/?referer=');">Global Summit on the Reliability of Global Underseas Communication Cable Infrstructure</a>&#8220;  (ROGUCCI for those in the know) in Dubai in October 2009 where experts came from all over the world to discuss how to keep our undersea cables safe and secure.  I took a look at the report from this conference and learned some other interesting facts about undersea cables:</p>
<ul>
<li>Undersea cables are one of the rare places here on Earth that we get to see the effects of the <a href="http://en.wikipedia.org/wiki/Speed_of_light" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Speed_of_light?referer=');">speed of light</a>.  As data or voice traffic takes its journey through cables, there can be a delay of up to a tenth of a second, which can be heard by humans and interfere with time sensitive data communications.  Satellite latency is even larger &#8211; this is one reason why all that intercontinental traffic can&#8217;t be rerouted via the heavens.</li>
</ul>
<p> </p>
<ul>
<li>Every second, the planet&#8217;s undersea cables carry 30 terabytes of information from continent to continent &#8211; and more data is added to this torrent every day.  (I think that 28T of that traffic is porn&#8230;)</li>
</ul>
<p> </p>
<ul>
<li>When there is a cable failure, traffic must be rerouted by other cables, making the path taken by the data much longer, increasing latency and adding traffic to links which may already be congested.  There is no Plan B for the undersea cable network.</li>
</ul>
<p> </p>
<ul>
<li><a href="http://www.iscpc.org/information/Cableships_Page.htm" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.iscpc.org/information/Cableships_Page.htm?referer=');">Cable ships </a>and their crews are a shared resource &#8211; the number of simultaneous repairs that can be performed is limited.  Time to repair is also extended due to some countries&#8217; bureaucratic permit processes which the repair ships must complete before entering their territorial waters to get to work.   Cable ships are also a potential target for pirates &#8211; cable operators worry that pirates could take over a cable ship and demand a hefty ransom for its release, delaying repairs further.  Pirates have <a href="http://allafrica.com/stories/200907270378.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/allafrica.com/stories/200907270378.html?referer=');">already caused problems </a>for cable laying off the coast of Africa.</li>
</ul>
<p> </p>
<ul>
<li>Threats to cables are on the rise; they are <a href="http://www.afji.com/2008/03/3463927/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.afji.com/2008/03/3463927/?referer=');">strategic targets in times of war</a> and are also threatened by the increasing mining of the ocean&#8217;s floor.  However, the importance of undersea cables was acknowledged as far back as 1884, when the major powers of the time signed the <a href="http://cil.nus.edu.sg/wp/wp-content/uploads/2009/10/Convention_on_Protection_of_Cables_1884.pdf" target="_blank" onclick="pageTracker._trackPageview('/outgoing/cil.nus.edu.sg/wp/wp-content/uploads/2009/10/Convention_on_Protection_of_Cables_1884.pdf?referer=');">International Convention for the Protection of Submarine Cables </a>in Paris.  Today, the <a href="http://www.iscpc.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.iscpc.org/?referer=');">International Cable Protection Committee </a>lobbies internationally (hence the name) to keep our undersea cables safe and secure.</li>
</ul>
<p>Undersea cable security needs to be on all of our agendas&#8230; the Internet links that allow me to post this blog entry from my hotel room in London are also the ones which major financial institutions use for moving money around the world and which an increasing amount of commerce depends on.    Governernments need to safeguard cables and cable repair ships and most importantly, build the redundant links which will allow our planetary nervous system to recover from damage.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F05%2F30%2Fterabits-and-risks-under-the-sea%2F&amp;linkname=terabits%20%28and%20risks%29%20under%20the%20sea" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F05_2F30_2Fterabits-and-risks-under-the-sea_2F_amp_linkname=terabits_20_28and_20risks_29_20under_20the_20sea&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/05/30/terabits-and-risks-under-the-sea/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>it&#8217;s (not always) nice to share&#8230;</title>
		<link>http://www.paranoidprose.com/2010/05/20/its-not-always-nice-to-share/</link>
		<comments>http://www.paranoidprose.com/2010/05/20/its-not-always-nice-to-share/#comments</comments>
		<pubDate>Fri, 21 May 2010 02:26:40 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=277</guid>
		<description><![CDATA[Now that Facebook has made their privacy settings just a bit less complex than, say, the US Tax Code or particle physics, now would be a really good time to check your privacy settings and make sure that you are not sharing more personal information with the world (or at least to the Internet connected [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Facebook2 " src="http://www.omcareers.org/blog/wp-content/uploads/2009/08/facebook-small-logo-thumb-360x360-75537-thumb-300x300-78195.png" alt="" width="240" height="240" />Now that Facebook has made their privacy settings just a bit less complex than, say, the US Tax Code or particle physics, now would be a really good time to check your privacy settings and make sure that you are not sharing more personal information with the world (or at least to the Internet connected portion thereof)  than you intended to.</p>
<p>The new settings default to sharing quite a bit of information &#8211; you may be (unpleasantly) surprised about what Facebook is telling the world about you.</p>
<p><a href="http://www.reclaimprivacy.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.reclaimprivacy.org/?referer=');">This website </a>provides a browser bookmarklet which will scan your <a href="http://www.nytimes.com/interactive/2010/05/12/business/facebook-privacy.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.nytimes.com/interactive/2010/05/12/business/facebook-privacy.html?referer=');">privacy settings</a> and let you know what you might want to change.   Take five minutes to protect your online privacy&#8230;</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F05%2F20%2Fits-not-always-nice-to-share%2F&amp;linkname=it%26%238217%3Bs%20%28not%20always%29%20nice%20to%20share%26%238230%3B" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F05_2F20_2Fits-not-always-nice-to-share_2F_amp_linkname=it_26_238217_3Bs_20_28not_20always_29_20nice_20to_20share_26_238230_3B&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/05/20/its-not-always-nice-to-share/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
